List all posts by Authors, nested Categories and Titles Security & Risk Analysis

wordpress.org/plugins/list-all-posts-by-authors-nested-categories-and-titles

This plugin lists all posts by Author, nested Categories and Title, allowing to place the lists in any page.

700 active installs v2.9.0 PHP + WP 4.0.1+ Updated Mar 28, 2024
authorsnested-categoriespoststitles
85
A · Safe
CVEs total1
Unpatched0
Last CVENov 29, 2023
Safety Verdict

Is List all posts by Authors, nested Categories and Titles Safe to Use in 2026?

Generally Safe

Score 85/100

List all posts by Authors, nested Categories and Titles has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Nov 29, 2023Updated 2yr ago
Risk Assessment

The 'list-all-posts-by-authors-nested-categories-and-titles' plugin version 2.9.0 demonstrates some good security practices, including 100% proper output escaping and the use of prepared statements for all SQL queries, which are crucial for preventing common web vulnerabilities. The absence of file operations and external HTTP requests further reduces the potential attack vectors.

However, the plugin has a notable security concern with one unprotected AJAX handler, representing a significant entry point that could be exploited if malicious input is not properly handled. While the static analysis found no critical or high severity taint flows and a complete absence of raw SQL queries, the existence of an unprotected AJAX endpoint remains a primary risk. The vulnerability history shows one past medium severity Cross-Site Scripting (XSS) vulnerability, which, although currently patched, indicates a potential weakness in input sanitization that could reappear if not carefully managed in future updates.

In conclusion, the plugin has strengths in its output handling and database query practices. Nevertheless, the unprotected AJAX handler is a direct security concern that requires immediate attention. The past XSS vulnerability also suggests a need for continued vigilance regarding input validation. The overall security posture is fair, with a critical area for improvement in access control for its entry points.

Key Concerns

  • Unprotected AJAX handler present
  • Past medium severity XSS vulnerability
Vulnerabilities
1 published

List all posts by Authors, nested Categories and Titles Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2023-49182medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

List all posts by Authors, nested Categories and Title <= 2.8.2 - Cross-Site Scripting

Nov 29, 2023 Patched in 2.8.3 (107d)
Version History

List all posts by Authors, nested Categories and Titles Release Timeline

v2.9.0Current
v2.8.5
v2.8.4
v2.8.3
v2.8.21 CVE
v2.8.11 CVE
v2.8.01 CVE
v2.7.101 CVE
v2.7.91 CVE
v2.7.81 CVE
v2.7.71 CVE
v2.7.61 CVE
v2.7.51 CVE
v2.7.41 CVE
v2.7.31 CVE
v2.7.21 CVE
v2.7.11 CVE
v2.7.01 CVE
v2.6.61 CVE
v2.6.51 CVE
Code Analysis
Analyzed Mar 16, 2026

List all posts by Authors, nested Categories and Titles Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
30 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped30 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
ACT_processform (include\ACT-admin.php:159)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

List all posts by Authors, nested Categories and Titles Attack Surface

Entry Points2
Unprotected1

AJAX Handlers 1

authwp_ajax_ACT_processformlist-all-posts-by-ACT.php:110

Shortcodes 1

[ACT-list] list-all-posts-by-ACT.php:53
WordPress Hooks 3
actionwp_enqueue_scriptslist-all-posts-by-ACT.php:61
actionadmin_enqueue_scriptslist-all-posts-by-ACT.php:86
actionadmin_menulist-all-posts-by-ACT.php:104
Maintenance & Trust

List all posts by Authors, nested Categories and Titles Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedMar 28, 2024
PHP min version
Downloads29K

Community Trust

Rating100/100
Number of ratings10
Active installs700
Developer Profile

List all posts by Authors, nested Categories and Titles Developer Profile

fmarzocca

2 plugins · 720 total installs

69
trust score
Avg Security Score
85/100
Avg Patch Time
107 days
View full developer profile
Detection Fingerprints

How We Detect List all posts by Authors, nested Categories and Titles

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about List all posts by Authors, nested Categories and Titles